
CAP PDF Dumps 2022 Exam Questions with Practice Test
Dumps for Free CAP Practice Exam Questions
Exam Overview
The CAP certification exam is 3 hours long. It contains 125 multiple-choice questions and can be taken in the English language only. To achieve success in the test, you must achieve the passing score of 700 points out of 1000. The registration process for the exam is done on the official website and the test is administered through Pearson VUE at any of its centers across the world.
NEW QUESTION 86
Tom is the project manager for his organization. In his project he has recently finished the risk response planning. He tells his manager that he will now need to update the cost and schedule baselines. Why would the risk response planning cause Tom the need to update the cost and schedule baselines?
- A. Risk responses may take time and money to implement.
- B. New or omitted work as part of a risk responsecan cause changes to the cost and/or schedule baseline.
- C. Risk responses protect the time and investment of the project.
- D. Baselines should not be updated, but refined through versions.
Answer: B
NEW QUESTION 87
Which of the following roles is responsible for review and risk analysis of all contracts on a regular basis?
- A. The Configuration Manager
- B. The IT Service Continuity Manager
- C. The Service Catalogue Manager
- D. The Supplier Manager
Answer: D
NEW QUESTION 88
DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
- A. Identification
- B. Accreditation
- C. Verification
- D. System Definition
- E. Validation
- F. Re-Accreditation
Answer: C,D,E,F
NEW QUESTION 89
Your organization has a project that is expected to last 20 months but the customer would really like the project completed in 18 months. You have worked on similar projects in the past and believe that you could fast track the project and reach the 18 month deadline. What increases when you fast track a project?
- A. Risks
- B. Costs
- C. Communication
- D. Resources
Answer: A
NEW QUESTION 90
Which of the following is NOT considered an environmental threat source?
- A. Chemical
- B. Hurricane
- C. Pollution
- D. Water
Answer: B
NEW QUESTION 91
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE?
Each correct answer represents a complete solution. Choose all that apply.
- A. An ISSE provides advice on the continuous monitoring of the information system.
- B. An ISSO takes part in the development activities that are required to implement system ch anges.
- C. An ISSE provides advice on the impacts of system changes.
- D. An ISSO manages the security of the information system that is slated for Certification &Accreditation (C&A).
- E. An ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).
Answer: A,C,D
NEW QUESTION 92
Adrian is the project manager of the NHP Project. In her project there are several work packages that deal with electrical wiring. Rather than to manage the risk internally she has decided to hire a vendor to complete all work packages that deal with the electrical wiring. By removing the risk internally to a licensed electrician Adrian feels more comfortable with project team being safe.
What type of risk response has Adrian used in this example?
- A. Transference
- B. Acceptance
- C. Avoidance
- D. Mitigation
Answer: A
Explanation:
Section: Volume A
NEW QUESTION 93
Risks with low ratings of probability and impact are included on a ____ for future monitoring.
- A. Observation list
- B. Watchlist
- C. Risk alarm
- D. Risk register
Answer: B
NEW QUESTION 94
Which of the following is used throughout the entire C&A process?
- A. DIACAP
- B. SSAA
- C. DAA
- D. DITSCAP
Answer: B
NEW QUESTION 95
During qualitative risk analysis you want to define the risk urgency assessment. All of the
following are indicators of risk priority except for which one?
- A. Cost of the project
- B. Risk rating
- C. Symptoms
- D. Warning signs
Answer: A
NEW QUESTION 96
You are preparing to start the qualitative risk analysis process for your project. You will be relying on some organizational process assets to influence the process. Which one of the following is NOT a probable reason for relying on organizational process assets as an input for qualitative risk analysis?
- A. Information on prior, similar projects
- B. Review of vendor contracts to examine risks in past projects
- C. Studies of similar projects by risk specialists
- D. Risk databases that may be available from industry sources
Answer: B
NEW QUESTION 97
Which of the following C&A professionals plays the role of an advisor?
- A. Information Owner
- B. Information System Security Engineer (ISSE)
- C. Chief Information Officer (CIO)
- D. Authorizing Official
Answer: B
NEW QUESTION 98
You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities. For your project archives, which one of the following is an output of risk monitoring and control?
- A. Risk audits
- B. Requested changes
- C. Qualitative risk analysis
- D. Quantitative risk analysis
Answer: B
Explanation:
Section: Volume A
Explanation/Reference:
NEW QUESTION 99
The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer?
Each correct answer represents a complete solution. Choose all that apply.
- A. Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
- B. Facilitating the sharing of security risk-related information among authorizing officials
- C. Establishing effective continuous monitoring program for the organization
- D. Preserving high-level communications and working group relationships in an organization
Answer: A,C,D
NEW QUESTION 100
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation?
Each correct answer represents a complete solution. Choose two.
- A. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- B. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
- C. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- D. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
Answer: B,C
Explanation:
Section: Volume D
NEW QUESTION 101
Which of the following is a temporary approval to operate based on an assessment of the implementation status of the assigned IA Controls?
- A. IATT
- B. IATO
- C. ATO
- D. DATO
Answer: B
Explanation:
Section: Volume B
NEW QUESTION 102
You are the project manager of the GHY project for your organization. You are working with
your project team to begin identifying risks for the project. As part of your preparation for identifying the risks within the project you will need eleven inputs for the process. Which one of the following is NOT an input to the risk identification process?
- A. Cost management plan
- B. Quality management plan
- C. Stakeholder register
- D. Procurement management plan
Answer: D
NEW QUESTION 103
You are the project manager of the CUL project in your organization. You and the project team are assessing the risk events and creating a probability and impact matrix for the identified risks.
Which one of the following statements best describes the requirements for the data type used in qualitative risk analysis?
- A. A qualitative risk analysis encourages biased data to reveal risk tolerances.
- B. A qualitative risk analysis requires accurate and unbiased data if it is to be credible.
- C. A qualitative risk analysis required unbiased stakeholders with biased risk tolerances.
- D. A qualitative risk analysis requires fast and simple data to complete the analysis.
Answer: B
Explanation:
Section: Volume C
NEW QUESTION 104
To help review or design security controls, they can be classified by several criteria. One of these criteria is based on time. According to this criteria, which of the following controls are intended to prevent an incident from occurring?
- A. Detective controls
- B. Corrective controls
- C. Preventive controls
- D. Adaptive controls
Answer: C
NEW QUESTION 105
Which of the following roles is used to ensure that the confidentiality, integrity, and availability of the services are maintained to the levels approved on the Service Level Agreement (SLA)?
- A. The IT Security Manager
- B. The Configuration Manager
- C. The Service Level Manager
- D. The Change Manager
Answer: A
Explanation:
Section: Volume C
NEW QUESTION 106
Which of the following phases begins with a review of the SSAA in the DITSCAP accreditation?
- A. Phase 3
- B. Phase 1
- C. Phase 4
- D. Phase 2
Answer: A
Explanation:
Section: Volume B
Explanation/Reference:
NEW QUESTION 107
You are the project manager for a construction project. The project includes a work that involves very high financial risks. You decide to insure processes so that any ill happening can be compensated. Which type of strategies have you used to deal with the risks involved with that particular work?
- A. Accept
- B. Avoid
- C. Transfer
- D. Mitigate
Answer: C
Explanation:
Section: Volume A
NEW QUESTION 108
......
Check your preparation for ISC CAP On-Demand Exam: https://examsboost.actualpdf.com/CAP-real-questions.html
